Datadog SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Datadog is required.

  • Please refer to the manual provided by Datadog for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser (*)

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser (*)

Android - Native App

(*) Login itself is possible via the in-app browser of the TrustLogin mobile app; however, since the in-app browser is not supported by Datadog, it may not function correctly.

Preparation

Datadog's SAML JIT supports the following two patterns.

  1. Sync the TrustLogin user's "Last Name," "First Name," and "Email Address" to manage Datadog user information (user role management is handled in Datadog)
  2. Sync the TrustLogin user's "Last Name," "First Name," "Email Address," and "Group" to manage Datadog user information and role mapping

If you are not using option 2, "Mapping to Datadog Roles," this preparation step is not required.
Please proceed to the next section, "TrustLogin Admin Page Settings."


Create a Group and Assign Members

Create a group to map to a Datadog role group, and assign members to it.
(You may use an existing group instead, if it suits your operations.)

For instructions on how to create a group and assign members, please refer to the following page.
Register a Group

[Configuration Example]

  • Create an "Administrator" group and assign it to Datadog's "Datadog Admin Role" role
  • Create a "General User" group and assign it to Datadog's "Datadog Standard Role" role

With this configuration, a user belonging to the "Administrator" group will automatically be assigned the "Datadog Admin Role" role when logging in to Datadog via SAML. Users who do not belong to any of the configured groups will not be able to log in to Datadog.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    jit02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information."
    03.png

Now, switch to configuring Datadog.
Do not click the "Register" button yet — open Datadog in a separate window.

Datadog Settings

Basic SAML Settings

  1. Log in to Datadog, open "Organization Settings" from the icon in the bottom left, and click the "Configure" button under "Login Methods > SAML."
    04.png

  2. Use the "Choose File" button to select the metadata you downloaded from TrustLogin, then click the "Upload and Enable" button.
    05.png

  3. Open the SAML settings screen again and check "Identity Provider (IdP) Initiated Login."
    Make a note of the "Single Sign-on URL," "Service Provider Entity ID," and the two "Assertion Consumer Service URL"
    values.
    jit06.png

  4. Specify the domain(s) allowed to create new users via SAML JIT, and add them using "Add Domain."
    jit07.png

  5. Specify the user role that is assigned by default when a new user is created via SAML JIT. (This does not update the roles of existing users, and does not apply if you are mapping to Datadog roles.)
    Save your settings by clicking the "Save Changes" button.
    jit08.png

Configuring Mapping to Datadog Roles

If you are not mapping to Datadog roles, this configuration is not required.
Please proceed to the next section, "TrustLogin Admin Page Settings (Continued)."

  1. Open "Organizarion Settings > SAML Group Mappings" and click "+New Mappping."
    jit09.png

  2. Under ① Add Attribute, enter "groups" and the group name you created during preparation, then under ② Assign Role, select the role to assign.
    Add it by clicking "Save & Close."
    jit10.png

  3. Create as many rules as needed for the roles you want to assign, then click "Enable Mappings." A confirmation screen will appear; click "Enable Mappings" again to activate the mapping.
    jit11.png

Return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Single Sign-on URL" obtained from Datadog
    Entity ID The "Service Provider Entity ID" obtained from Datadog
    Name ID Format "emailAddress"
    ACS URL to Service

    Click the "+" on the right to add a row.
    Enter the two "Assertion Consumer Service URL" values obtained from Datadog
    into the two rows. The order does not matter.


    jit15.png

  2. Click the "Specify Custom Attribute" button under "SAML Attribute Settings," then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.

    The groups row should only be configured if you are mapping to Datadog roles.
    For the group attribute value, select the group name from the dropdown; you can add multiple groups using the "+" mark on the right.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value

    urn:mace:dir:attribute-def:eduPersonPrincipalName

    Basic

    urn:mace:dir:attribute-def:eduPersonPrincipalName

    Member Member - Email Address
    urn:mace:dir:attribute-def:sn Basic urn:mace:dir:attribute-def:sn Member Member - Last Name
    urn:mace:dir:attribute-def:givenName Basic urn:mace:dir:attribute-def:givenName Member Member - First Name
    groups Basic groups Group Select the group name you configured and add it using the "+" button

    [If you are not mapping to Datadog roles]
    jit14.png

    [If you are mapping to Datadog roles]
    jit13.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the browser extension, and confirm that login succeeds.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Log In via the Datadog Mobile App

  1. Log in to the TrustLogin mobile app in advance.

  2. Open the mobile app, select your region, and click the "Sign In" button.
    08.png

  3. Click "Using Single Sign-On (SAML)?"
    On the next screen, enter your email address and send it by clicking "Send email."
    09.png 10.png

  4. You will receive an email containing a login URL at your email address; open the "Mobile Login" link on your mobile device. Login will be complete once you click the "Authorize" button in the mobile app.
    11.png

Datadog SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Datadog is required.

  • Please refer to the manual provided by Datadog for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser (*)

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser (*)

Android - Native App

(*) Login itself is possible via the in-app browser of the TrustLogin mobile app; however, since the in-app browser is not supported by Datadog, it may not function correctly.

Preparation

Datadog's SAML JIT supports the following two patterns.

  1. Sync the TrustLogin user's "Last Name," "First Name," and "Email Address" to manage Datadog user information (user role management is handled in Datadog)
  2. Sync the TrustLogin user's "Last Name," "First Name," "Email Address," and "Group" to manage Datadog user information and role mapping

If you are not using option 2, "Mapping to Datadog Roles," this preparation step is not required.
Please proceed to the next section, "TrustLogin Admin Page Settings."


Create a Group and Assign Members

Create a group to map to a Datadog role group, and assign members to it.
(You may use an existing group instead, if it suits your operations.)

For instructions on how to create a group and assign members, please refer to the following page.
Register a Group

[Configuration Example]

  • Create an "Administrator" group and assign it to Datadog's "Datadog Admin Role" role
  • Create a "General User" group and assign it to Datadog's "Datadog Standard Role" role

With this configuration, a user belonging to the "Administrator" group will automatically be assigned the "Datadog Admin Role" role when logging in to Datadog via SAML. Users who do not belong to any of the configured groups will not be able to log in to Datadog.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    jit02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information."
    03.png

Now, switch to configuring Datadog.
Do not click the "Register" button yet — open Datadog in a separate window.

Datadog Settings

Basic SAML Settings

  1. Log in to Datadog, open "Organization Settings" from the icon in the bottom left, and click the "Configure" button under "Login Methods > SAML."
    04.png

  2. Use the "Choose File" button to select the metadata you downloaded from TrustLogin, then click the "Upload and Enable" button.
    05.png

  3. Open the SAML settings screen again and check "Identity Provider (IdP) Initiated Login."
    Make a note of the "Single Sign-on URL," "Service Provider Entity ID," and the two "Assertion Consumer Service URL"
    values.
    jit06.png

  4. Specify the domain(s) allowed to create new users via SAML JIT, and add them using "Add Domain."
    jit07.png

  5. Specify the user role that is assigned by default when a new user is created via SAML JIT. (This does not update the roles of existing users, and does not apply if you are mapping to Datadog roles.)
    Save your settings by clicking the "Save Changes" button.
    jit08.png

Configuring Mapping to Datadog Roles

If you are not mapping to Datadog roles, this configuration is not required.
Please proceed to the next section, "TrustLogin Admin Page Settings (Continued)."

  1. Open "Organizarion Settings > SAML Group Mappings" and click "+New Mappping."
    jit09.png

  2. Under ① Add Attribute, enter "groups" and the group name you created during preparation, then under ② Assign Role, select the role to assign.
    Add it by clicking "Save & Close."
    jit10.png

  3. Create as many rules as needed for the roles you want to assign, then click "Enable Mappings." A confirmation screen will appear; click "Enable Mappings" again to activate the mapping.
    jit11.png

Return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Single Sign-on URL" obtained from Datadog
    Entity ID The "Service Provider Entity ID" obtained from Datadog
    Name ID Format "emailAddress"
    ACS URL to Service

    Click the "+" on the right to add a row.
    Enter the two "Assertion Consumer Service URL" values obtained from Datadog
    into the two rows. The order does not matter.


    jit15.png

  2. Click the "Specify Custom Attribute" button under "SAML Attribute Settings," then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.

    The groups row should only be configured if you are mapping to Datadog roles.
    For the group attribute value, select the group name from the dropdown; you can add multiple groups using the "+" mark on the right.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value

    urn:mace:dir:attribute-def:eduPersonPrincipalName

    Basic

    urn:mace:dir:attribute-def:eduPersonPrincipalName

    Member Member - Email Address
    urn:mace:dir:attribute-def:sn Basic urn:mace:dir:attribute-def:sn Member Member - Last Name
    urn:mace:dir:attribute-def:givenName Basic urn:mace:dir:attribute-def:givenName Member Member - First Name
    groups Basic groups Group Select the group name you configured and add it using the "+" button

    [If you are not mapping to Datadog roles]
    jit14.png

    [If you are mapping to Datadog roles]
    jit13.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the browser extension, and confirm that login succeeds.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Log In via the Datadog Mobile App

  1. Log in to the TrustLogin mobile app in advance.

  2. Open the mobile app, select your region, and click the "Sign In" button.
    08.png

  3. Click "Using Single Sign-On (SAML)?"
    On the next screen, enter your email address and send it by clicking "Send email."
    09.png 10.png

  4. You will receive an email containing a login URL at your email address; open the "Mobile Login" link on your mobile device. Login will be complete once you click the "Authorize" button in the mobile app.
    11.png